Egret Nest · Changelog
What shipped in Egret Nest.
Released changes for the dashboard, synced from the repo. See the roadmap, or the Egret agent changelog.
Changelog
Notable changes to Egret Nest Dashboard, following Keep a Changelog and Semantic Versioning.
[0.2.0] - Security hardening (pentest remediation)
Changed (upgrade impact)
- The server refuses to start without
EGRET_NEST_SECRET_KEYwhen TOTP data would otherwise be stored unencrypted. Set the key, or explicitly opt into the old behavior withEGRET_NEST_ALLOW_PLAINTEXT_TOTP=1. This was previously a warning that silently continued with plaintext TOTP seeds at rest. - SSO login is refused until first-run setup is complete. A brand-new SSO account can no longer be auto-provisioned before the instance is bootstrapped, closing a race where an early SSO login could permanently lock the operator out of the admin console.
- The Helm chart now defaults
networkPolicy.enabled: true(default-deny egress). It degrades gracefully on a CNI that doesn’t enforce NetworkPolicy. - Default deployment examples pin a released image tag instead of
latest(compose,.env.example, docs); floating tags are noted as convenience-only.
Security
- First-run bootstrap is race-safe. The
bootstrappedstate is claimed atomically alongside admin creation, and SSO provisioning + the/setupgate both key off it, so exactly one admin is ever created (verified under concurrent load). - Login no longer leaks account existence via timing. The unknown-user / SSO-only path now runs a dummy argon2id verification so it costs the same as a real wrong-password attempt.
- Container images are vulnerability-scanned before publish. The release workflow runs Trivy (fail on HIGH/CRITICAL) between build and push.
- CI/CD hardening:
concurrencycancellation on PR workflows. - The one-time setup token is accessed atomically (
atomic.Pointer), fixing a data race under concurrent/setuprequests.
Changed
- Ingress TLS enforcement is configurable (
ingress.sslRedirect), and the docs recommendexistingSecret(SOPS / External Secrets / Vault) as the primary way to supply secrets rather than plaintextvalues.yaml.
0.1.1 - Brand, distribution, and hardening
Added
- Docker Hub distribution. The container image is mirrored to
nx1x/egret-nestalongside GHCR, with floatinglatest/v0/v0.1tags, and the Docker Hub repo overview is kept in sync with the README. - Go fuzzing over the untrusted-input parsing paths, plus contributor onboarding docs.
Changed
- New visual identity - an egret-in-flight mark across the icon, app-icon, logo (a self-contained dark-card lockup), favicon, and social preview; the README now leads with the logo.
- Wider security policy in SECURITY.md - explicit safe harbor for good-faith research, response-time targets, coordinated disclosure, and reporter credit (plain email, no PGP required).
Security
- Go toolchain 1.26.5 and refreshed digest-pinned Actions and base images (clears the stdlib advisories).
0.1.0 - first release
The optional self-hosted dashboard for Egret: ingest CI/CD runs and view egress over time, endpoint drift, and violations across your fleet, with multi-tenant access control. Ships as a single Go binary with embedded SQLite - no external services required.
Added
- Run ingest + history. The Egret agent/Action POSTs each run; stored in embedded SQLite. Run list/detail, per-repo egress-over-time, org fleet view, and new-endpoint drift (inline-SVG sparklines, no JavaScript).
- Authentication - one core, three providers. Local accounts (argon2id) with self-service TOTP 2FA, GitHub OAuth, and generic OIDC (Okta / Entra / Google), configurable via env or an admin UI (client secrets encrypted at rest, env always wins).
- Authorization (multi-tenant RBAC). Organizations → repositories → runs, with fail-closed org membership (SSO authenticates identity; an admin grants access), per-org roles (owner/admin/member/viewer), and scoped, revocable ingest tokens.
- Admin console. Settings, connect-a-repo, user management, audit log, live access log, and retention controls.
- Deploy. Dockerfile, hardened
docker-compose(+ optional nginx TLS), a Helm chart,healthcheck+backupcommands, and a deployment guide.
Security
- Hardened for crown-jewel data: native TLS (or behind a proxy),
__Host-cookies, CSRF on every mutation, a strict CSP (script-src 'none'), argon2id password hashing, AES-256-GCM secrets at rest, HMAC-verified webhooks, token-gated metrics, and an audit trail. - SSRF-guarded OIDC: every OIDC fetch for a UI-configured issuer refuses internal addresses at dial time (closes DNS-rebinding and attacker-declared-endpoint holes).
- Supply chain: digest-pinned base images, SHA-pinned Actions, container CVE
scanning (Trivy),
govulncheck, and CodeQL.